Описание
In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the SERVICEACCOUNT_TOKEN placeholder (Canal/Flannel-Calico deployments), the installer substitutes the live Kubernetes ServiceAccount bearer token before logging, exposing the token to any authenticated user with pods/log permission in the namespace with calico-node. The token holds patch privileges on pods/status, enabling annotation-based attacks against cluster workloads. The default kubeconfig-based authentication path is not affected. This is a direct regression of TTA-2018-001.
Ссылки
- Issue TrackingPatch
- Issue TrackingPatch
- Issue TrackingPatch
- MitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.21.7 (исключая)Версия до 3.32.0 (исключая)Версия до 22.4.0 (исключая)Версия от 3.22.0 (включая) до 3.22.3 (исключая)
Одно из
cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:tigera:calico:*:*:*:*:open_source:*:*:*
cpe:2.3:a:tigera:calico:*:*:*:*:cloud:*:*:*
cpe:2.3:a:tigera:calico:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 40%
0.00504
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-532
Связанные уязвимости
EPSS
Процентиль: 40%
0.00504
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-532